|
210871
|
8.8 |
HIGH
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious u…
|
CWE-22
Path Traversal
|
CVE-2020-14490
|
2024-11-21 14:03 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210872
|
7.5 |
HIGH
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-14489
|
2024-11-21 14:03 |
2020-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210873
|
4.9 |
MEDIUM
Network
|
oracle netapp
|
mysql active_iq_unified_manager
|
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privi…
|
NVD-CWE-noinfo
|
CVE-2020-14725
|
2024-11-21 14:03 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210874
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow u…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-14494
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210875
|
6.5 |
MEDIUM
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.
|
CWE-862
Missing Authorization
|
CVE-2020-14491
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210876
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, which may allow exec…
|
CWE-287
Improper Authentication
|
CVE-2020-14485
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210877
|
9.8 |
CRITICAL
Network
|
openclinic_ga_project
|
openclinic_ga
|
OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-14484
|
2024-11-21 14:03 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210878
|
7.3 |
HIGH
Local
|
oracle
|
solaris
|
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Device Driver Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged …
|
NVD-CWE-noinfo
|
CVE-2020-14724
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210879
|
8.2 |
HIGH
Network
|
oracle
|
help_technologies
|
Vulnerability in the Oracle Help Technologies product of Oracle Fusion Middleware (component: Web UIX). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerab…
|
NVD-CWE-noinfo
|
CVE-2020-14723
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210880
|
5.8 |
MEDIUM
Network
|
oracle
|
enterprise_communications_broker
|
Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications Applications (component: WebGUI). Supported versions that are affected are 3.0.0-3.2.0. Difficult to expl…
|
NVD-CWE-noinfo
|
CVE-2020-14722
|
2024-11-21 14:03 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|